THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Books and ideas worth revisiting

Security books, adjacent thinking, and the concepts that improve how defenders reason and communicate.

Personal reading notes, not affiliate recommendations.

Robert M. Lee & Rebekah BrownRecommended

Intelligence-Driven Incident Response

A useful bridge between intelligence practice and the operational reality of incident response.

IntelligenceIncident response
Brief overview

Key idea: indicators describe artifacts; adversary behavior provides context that can improve both investigation and future detection.

Richard BejtlichCore reading

The Practice of Network Security Monitoring

A foundation for thinking about visibility, evidence, and network-centric investigation.

NSMOperations
Brief overview

Key idea: collection is valuable only when it supports analysis, escalation, and a repeatable response process.

David BiancoConcept note

The Pyramid of Pain

A compact model for understanding which detections create the greatest cost for an adversary.

DetectionThreat hunting
Brief overview

Key idea: detections based on tools, techniques, and behavior tend to be more durable than atomic indicators.

Donella MeadowsAdjacent reading

Thinking in Systems

Not a security book, but a powerful guide to feedback, structure, and unintended consequences.

SystemsStrategy
Brief overview

Key idea: defensive outcomes emerge from incentives, delays, workflows, and feedback loops—not isolated controls.